Optimizing endpoint detection and monitoring in enterprise solution: A cyber threat intelligence approach

bracu.type.groupResearch Publications
datacite.rightsMetadata Only
dc.contributor.authorSarker, Apurba
dc.contributor.authorMondal, Joty Prokash
dc.contributor.authorSeraj, Mehnaz
dc.contributor.authorNoor, Jannatun
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-09-30T04:49:13Z
dc.date.available2026-09-30T04:49:13Z
dc.date.issued2024-01-01
dc.description.abstractAdvanced cyber threat intelligence systems are crucial at a time when enterprise solutions are increasing and are being targeted by more sophisticated cyberattacks. This research aims to improve endpoint detection and monitoring in enterprises by installing a Security Information and Event Management (SIEM) system based on Wazuh having an open-source robust and flexible Host Intrusion Detection System (HIDS) with integration into ELK Stack. The infrastructure creates a powerful combination of analytical security, intrusion detection, log data analysis, file integrity monitoring (FIM), and vulnerability management capabilities using the Wazuh active response module to detect security threats and continuous monitoring. Wazuh provides a robust and cost-effective solution that instantly detects and monitors simulated attacks such as denial-of-service (DoS) attacks by spotting suspicious file changes in real-time, SSH authentication failure, and identifying the root source of the flood of requests. This study also provides useful insights on designing and deploying comprehensive cybersecurity solutions with open-source tools such as Wazuh, making visual insights for file integrity monitoring (FIM) in real time.
dc.description.versionPublished
dc.format.extent6 Pages
dc.identifier.citationA. Sarker, J. P. Mondal, M. Seraj and J. Noor, "Optimizing endpoint detection and monitoring in enterprise solution: A cyber threat intelligence approach," 2024 27th International Conference on Computer and Information Technology (ICCIT), Cox's Bazar, Bangladesh, 2024, pp. 2683-2688, doi: 10.1109/ICCIT64611.2024.11021895.
dc.identifier.doi10.1109/ICCIT64611.2024.11021895
dc.identifier.issn9798331519094
dc.identifier.other2-s2.0-105009160235
dc.identifier.urihttps://hdl.handle.net/10361/30301
dc.language.isoen_US
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.hasversion10.1109/ICCIT64611.2024.11021895
dc.relation.ispartof2024 27th International Conference on Computer and Information Technology Iccit 2024 Proceedings
dc.relation.ispartofseries2024 27th International Conference on Computer and Information Technology Iccit 2024 Proceedings
dc.relation.urihttps://ieeexplore.ieee.org/document/11021895
dc.subjectVisualization
dc.subjectPrivacy
dc.subjectScalability
dc.subjectPipelines
dc.subjectNetwork intrusion detection
dc.subjectReal-time systems
dc.subjectThreat assessment
dc.subjectMalware
dc.subjectCyber threat intelligence
dc.subjectMonitoring
dc.subjectWazuh
dc.subjectSecurity Information and Event Management (SIEM)
dc.subjectELK Stack
dc.subjectEndpoint detection
dc.subjectReal-time monitoring
dc.subjectDenial of Service (DoS) attack
dc.subjectBrute-force attack
dc.subjectFile Integrity Monitoring (FIM)
dc.subjectElastic-search
dc.subjectFilebeat
dc.subject.lcshComputer security.
dc.titleOptimizing endpoint detection and monitoring in enterprise solution: A cyber threat intelligence approach
dc.typeConference Proceeding
person.affiliation.nameBRAC University
person.affiliation.nameBRAC University
person.affiliation.nameBRAC University
person.affiliation.nameBRAC University
person.identifier.scopus-author-id59964437800
person.identifier.scopus-author-id59963990500
person.identifier.scopus-author-id59963990600
person.identifier.scopus-author-id57193917145

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
IMG_8345.jpg
Size:
27.35 KB
Format:
Joint Photographic Experts Group/JPEG File Interchange Format (JFIF)

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: